Help!

Malware Bytes Scan

 
Goto page 1, 2
Post new topic   General Reply to Topic (not reply to a specific post)    Forums Home -> General Discussions RSS
Next:  Charitable Organizations?  
Author Message
Dave Cohen
External


Since: Oct 16, 2004
Posts: 59



PostPosted: Thu Dec 03, 2009 3:54 pm    Post subject: Malware Bytes Scan
Archived from groups: alt>comp>anti-virus (more info?)

Just updated MalwareByte and scanned system. Getting over 400
'Trojan.Downloader' messages on files that have been on the system
forever. Avira doesn't find anything.
Back to top
Victek
External


Since: Dec 03, 2009
Posts: 2



PostPosted: Thu Dec 03, 2009 3:54 pm    Post subject: Re: Malware Bytes Scan [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

> Just updated MalwareByte and scanned system. Getting over 400
> 'Trojan.Downloader' messages on files that have been on the system
> forever. Avira doesn't find anything.
..
I would trust MBAM, but if you want a second opinion install Hitman Pro
(free thirty day license) or SuperAntiSpyware. I find that AV is
notoriously unable to detect the types of malware that MBAM, SAS etc. are
designed to find/remove.
Back to top
FredW
External


Since: May 03, 2009
Posts: 30



PostPosted: Thu Dec 03, 2009 5:10 pm    Post subject: Re: Malware Bytes Scan [Login to view extended thread Info.]
Imported from groups: per prev. post (more info?)

This message is not archived
Back to top
Rube Bumpkin
External


Since: Dec 03, 2009
Posts: 3



PostPosted: Thu Dec 03, 2009 6:19 pm    Post subject: Re: Malware Bytes Scan [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

FredW wrote:
> On Thu, 03 Dec 2009 15:54:29 -0500, Dave Cohen wrote:
>
>> Just updated MalwareByte and scanned system. Getting over 400
>> 'Trojan.Downloader' messages on files that have been on the system
>> forever. Avira doesn't find anything.
>
> Are you sure it is MBAM and not Avast?
> Wink
>
> I would wait for the next update and then scan again.
>
> In the meantime for a second opinion
> - SuperAntiSpyware (Free Edition)
> http://www.superantispyware.com/download.html
>
This was a problem with Update 3286 which was only out there for a
little while. It was replaced with 3287, then 3288.

There were several threads on the MBAM forums.

RB
Back to top
FredW
External


Since: May 03, 2009
Posts: 30



PostPosted: Thu Dec 03, 2009 7:10 pm    Post subject: Re: Malware Bytes Scan [Login to view extended thread Info.]
Imported from groups: per prev. post (more info?)

This message is not archived
Back to top
Buffalo
External


Since: Jul 19, 2007
Posts: 20



PostPosted: Thu Dec 03, 2009 7:10 pm    Post subject: Re: Malware Bytes Scan [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

FredW wrote:
>
> Looks like the same kind of problem Avast had today.

Huh? Why did MBAM and Avast have problems around the same time?
What is the connection??
Do they share or steal each others definitions?
Buffalo
Back to top
FromTheRafters
External


Since: Feb 16, 2009
Posts: 78



PostPosted: Thu Dec 03, 2009 8:10 pm    Post subject: Re: Malware Bytes Scan [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

"Dave Cohen" wrote in message

> Just updated MalwareByte and scanned system. Getting over 400
> 'Trojan.Downloader' messages on files that have been on the system
> forever. Avira doesn't find anything.

Submit one of the suspect files to Virustotal or Jotti to help ascertain
if it is a false positive.
Back to top
David H. Lipman
External


Since: Jul 04, 2003
Posts: 2245



PostPosted: Thu Dec 03, 2009 8:30 pm    Post subject: Re: Malware Bytes Scan [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

From: "Buffalo"



| FredW wrote:

>> Looks like the same kind of problem Avast had today.

| Huh? Why did MBAM and Avast have problems around the same time?
| What is the connection??
| Do they share or steal each others definitions?
| Buffalo



Pure coincidence of a rash of False Positives!

--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp
Back to top
Buffalo
External


Since: Jul 19, 2007
Posts: 20



PostPosted: Thu Dec 03, 2009 8:30 pm    Post subject: Re: Malware Bytes Scan [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

David H. Lipman wrote:
> From: "Buffalo"
>
>
>
>> FredW wrote:
>
>>> Looks like the same kind of problem Avast had today.
>
>> Huh? Why did MBAM and Avast have problems around the same time?
>> What is the connection??
>> Do they share or steal each others definitions?
>> Buffalo
>
>
>
> Pure coincidence of a rash of False Positives!

I really don't believe that explaination!
Buffalo
Back to top
Rube Bumpkin
External


Since: Dec 03, 2009
Posts: 3



PostPosted: Thu Dec 03, 2009 10:18 pm    Post subject: Re: Malware Bytes Scan [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

FromTheRafters wrote:
> "Dave Cohen" wrote in message
>
>> Just updated MalwareByte and scanned system. Getting over 400
>> 'Trojan.Downloader' messages on files that have been on the system
>> forever. Avira doesn't find anything.
>
> Submit one of the suspect files to Virustotal or Jotti to help ascertain
> if it is a false positive.
>
>

I did that. When it came back 'negative', I checked the MBAM forums.

RB
Back to top
David H. Lipman
External


Since: Jul 04, 2003
Posts: 2245



PostPosted: Thu Dec 03, 2009 10:46 pm    Post subject: Re: Malware Bytes Scan [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

From: "Buffalo"


>> Pure coincidence of a rash of False Positives!

| I really don't believe that explaination!
| Buffalo


Sorry, that's the way it is.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp
Back to top
FredW
External


Since: May 03, 2009
Posts: 30



PostPosted: Fri Dec 04, 2009 7:10 am    Post subject: Re: Malware Bytes Scan [Login to view extended thread Info.]
Imported from groups: per prev. post (more info?)

This message is not archived
Back to top
FromTheRafters
External


Since: Feb 16, 2009
Posts: 78



PostPosted: Fri Dec 04, 2009 7:22 am    Post subject: Re: Malware Bytes Scan [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

"Buffalo" wrote in message

>
>
> David H. Lipman wrote:
>> From: "Buffalo"
>>
>>
>>
>>> FredW wrote:
>>
>>>> Looks like the same kind of problem Avast had today.
>>
>>> Huh? Why did MBAM and Avast have problems around the same time?
>>> What is the connection??
>>> Do they share or steal each others definitions?
>>> Buffalo
>>
>>
>>
>> Pure coincidence of a rash of False Positives!
>
> I really don't believe that explaination!

If it were more than a coincidence, it would be the *same* malware being
purportedly found by each program, since you are talking about the def
files being possibly shared or stolen. For example if both entities
stole their defs from PCButts - all three would FP on the same files for
the same malware (possibly giving different malware names as a result).
Back to top
FromTheRafters
External


Since: Feb 16, 2009
Posts: 78



PostPosted: Fri Dec 04, 2009 7:28 am    Post subject: Re: Malware Bytes Scan [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

"Rube Bumpkin" wrote in message

> FromTheRafters wrote:
>> "Dave Cohen" wrote in message
>>
>>> Just updated MalwareByte and scanned system. Getting over 400
>>> 'Trojan.Downloader' messages on files that have been on the system
>>> forever. Avira doesn't find anything.
>>
>> Submit one of the suspect files to Virustotal or Jotti to help
>> ascertain if it is a false positive.
>
> I did that. When it came back 'negative', I checked the MBAM forums.

Even the best programs can and will FP - it is nice to have a
programmatical consensus available online. When online is not possible,
it is nice to have an alternative program available locally for a second
opinion.
Back to top
Dave Cohen
External


Since: Oct 16, 2004
Posts: 59



PostPosted: Fri Dec 04, 2009 12:11 pm    Post subject: Re: Malware Bytes Scan [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Dave Cohen wrote:
> Just updated MalwareByte and scanned system. Getting over 400
> 'Trojan.Downloader' messages on files that have been on the system
> forever. Avira doesn't find anything.

All is well. My 12/3 update installed 3287 and the scan indicated
problems I stated.
Today (12/4) I updated and installed 3289, full scan showed zero problems.
One curious note: I don't recall having to re-start the computer after
yesterday's update. Today I received and responded to that message.
Thanks for all your replies.
Back to top
Buffalo
External


Since: Jul 19, 2007
Posts: 20



PostPosted: Fri Dec 04, 2009 1:13 pm    Post subject: Re: Malware Bytes Scan [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

David H. Lipman wrote:
> From: "Buffalo"
>
>
>>> Pure coincidence of a rash of False Positives!
>
>> I really don't believe that explanation!
>> Buffalo
>
>
> Sorry, that's the way it is.

I guess so. That kind of coincidence just throws up a red flag to me.
Thanks for the response.
Buffalo
Back to top
Leonard Agoado
External


Since: Jul 22, 2006
Posts: 5



PostPosted: Fri Dec 04, 2009 1:37 pm    Post subject: Re: Malware Bytes Scan [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

"FromTheRafters" wrote


> For example if both entities stole their defs from
> PCButts - all three would FP on the same files for the same malware...


FTR,

Do you imagine, in the scenario described above, either entity
functioning well enough to make it to that point?

Regards,

Len Agoado
agoado.TakeThisOut@msn.com
Back to top
David H. Lipman
External


Since: Jul 04, 2003
Posts: 2245



PostPosted: Fri Dec 04, 2009 5:26 pm    Post subject: Re: Malware Bytes Scan [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

From: "Buffalo"



| David H. Lipman wrote:
>> From: "Buffalo"


>>>> Pure coincidence of a rash of False Positives!

>>> I really don't believe that explanation!
>>> Buffalo


>> Sorry, that's the way it is.

| I guess so. That kind of coincidence just throws up a red flag to me.
| Thanks for the response.
| Buffalo


I understand.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp
Back to top
FromTheRafters
External


Since: Feb 16, 2009
Posts: 78



PostPosted: Fri Dec 04, 2009 6:05 pm    Post subject: Re: Malware Bytes Scan [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

"Leonard Agoado" wrote in message

>
> "FromTheRafters" wrote
>
>
>> For example if both entities stole their defs from
>> PCButts - all three would FP on the same files for the same
>> malware...
>
>
> FTR,
>
> Do you imagine, in the scenario described above, either entity
> functioning well enough to make it to that point?

Of course, virus (or malware) description language is not a programming
language.

SurprisedD

Butt's programs work reasonably well even though the data files
describing the malware are stolen from the actual people doing the
research to create them (the "engines" consuming that data are probably
stolen as well, by this has not been demonstrated as well as the other
aspect has).

If you recall the "other" thieves (from China?) - they actually gave the
same malware name (marker) in the alert, probably because the engine
(maybe even the GUI) is stolen as well.
Back to top
FromTheRafters
External


Since: Feb 16, 2009
Posts: 78



PostPosted: Fri Dec 04, 2009 6:09 pm    Post subject: Re: Malware Bytes Scan [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

"Dave Cohen" wrote in message

> Dave Cohen wrote:
>> Just updated MalwareByte and scanned system. Getting over 400
>> 'Trojan.Downloader' messages on files that have been on the system
>> forever. Avira doesn't find anything.
>
> All is well. My 12/3 update installed 3287 and the scan indicated
> problems I stated.
> Today (12/4) I updated and installed 3289, full scan showed zero
> problems.
> One curious note: I don't recall having to re-start the computer after
> yesterday's update. Today I received and responded to that message.
> Thanks for all your replies.

Often, that is indicative of a program update as opposed to just a
definitions update. I'm not sure if Malwarebyte's Anti-Malware shares
this nature so familiar with the AV programs.
Back to top
Display posts from previous:   
Post new topic   General Reply to Topic (not reply to a specific post)    Forums Home -> General Discussions All times are: Eastern Time (US & Canada)
Goto page 1, 2
Page 1 of 2

 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum